MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c724ade25970a7471e639c8524e4d1c60ee642a7c72706091d07c93a5b7cd562. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara Comments

SHA256 hash: c724ade25970a7471e639c8524e4d1c60ee642a7c72706091d07c93a5b7cd562
SHA3-384 hash: bbd96cf7543656ee60c2822a9a6fb8456b7d3c14ff79588f818a3aee8549968e19699283d0ee0e25523fe303e0eaeabf
SHA1 hash: c0a6b124548becb40d835a425dd4f7c9fca07bda
MD5 hash: 1a37e894fb0aa81871016174ed24aa37
humanhash: ink-princess-twelve-lima
File name:Akbank Hesap Özetiniz.r00
Download: download sample
Signature AgentTesla
File size:608'299 bytes
First seen:2020-07-31 09:54:34 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:T5wNRUBYtuVZaW5cJTSwKgc0SW/qzclEHS+aFVa8Y98x9CRldzuKk:T5AatZSTNKg/B/qQlEHS+aYSx9Qpdk
TLSH DFD423F243733C26B06A4A95D936E31C42FA0A947779E3EA95B2FD84FDDA6670301344
Reporter @abuse_ch
Tags:AgentTesla Akbank geo r00 TUR


Twitter
@abuse_ch
Malspam distributing AgentTesla:

HELO: correo.natxo.cat
Sending IP: 81.21.67.230
From: AKBANK <ticaribankacilik@bilgi.akbank.com>
Subject: HAZİRAN 2020 Akbank Beyanı (Ref: 9185232345)
Attachment: Akbank Hesap Özetiniz.r00 (contains "Akbank Hesap Özetiniz.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
US US
Mail intelligence
Geo location:
Global
Volume:
Low
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-31 09:56:06 UTC
AV detection:
11 of 48 (22.92%)
Threat level
  5/5
Threat name:
Legit
Score:
0.00

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 c724ade25970a7471e639c8524e4d1c60ee642a7c72706091d07c93a5b7cd562

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments